Ali Zamanian Startup Legal Strategy
AI, Data & Contracts6 min read

US state AI laws in 2026: what startups actually have to do.

There is no single US AI law. There is a patchwork, and in mid-2026 it visibly shifted: Colorado repealed and replaced its landmark AI Act with something narrower, while Texas, Illinois, and California rules came online. Here is the map, the pattern behind it, and the short list a lean team should actually act on.

If you have been trying to follow US state AI laws through headlines, you have whiplash by now, and mid-2026 made it worse: Colorado, whose 2024 act was the model everyone benchmarked against, repealed and replaced it before it ever took effect. Here is the honest orientation: there is no single US AI law, the patchwork is real, and yet the practical burden for a startup concentrates in two places that have stayed stable while the statutes churned: consequential decisions about people, and honesty with consumers about AI. Map those two, and the patchwork gets much less frightening.

This guide walks the Colorado story (because it explains the direction of travel), the rules actually in effect now, the pattern underneath them, and the short list worth doing this quarter. It is the US companion to does the EU AI Act apply to your US startup.

Colorado: the bellwether that blinked

Colorado's SB 24-205, enacted in 2024, was the first comprehensive state AI act: a risk-based framework targeting algorithmic discrimination in "high-risk" AI systems used in consequential decisions (employment, housing, health care, education, and similar), with duties of care for developers and deployers, impact assessments, risk-management programs, and attorney-general reporting. It was scheduled to take effect in 2026, first February, then delayed to June 30.

It never got there. Facing sustained pressure that the framework would bury startups in administrative burden, Colorado's legislature passed, and in May 2026 the governor signed, a repeal-and-replace: the revised law eliminates the duty-of-care and impact-assessment architecture and refocuses on disclosure and transparency around certain automated decision systems, now effective January 1, 2027. Whatever the final details look like when guidance arrives, the direction matters more than the statute: even the most ambitious state pulled back from EU-style process obligations toward disclosure duties, and every other legislature watched it happen.

Which state AI laws are in effect right now

Regulators keep converging on two questions: does your AI decide things about people, and do people know they are dealing with AI? Answer those well and most of the patchwork follows.

The pattern underneath the patchwork

Strip the statute names and the pattern is consistent. First, consequential decisions. AI that influences employment, credit, housing, insurance, health care, or education triggers the heaviest obligations everywhere: bias concerns, notice, sometimes audits, sometimes human-review rights. This mirrors the EU's high-risk category, and it is the same lens investors and enterprise customers apply in procurement diligence. Second, disclosure. Consumer-facing AI attracts transparency duties: disclose the interaction, label synthetic content where required, be honest about capabilities. Existing law fills the rest: deceptive-practices statutes, discrimination law, and privacy law all apply to AI without needing the letters A and I in the title.

What a lean startup should actually do this quarter

// what to take from this
  • No single US AI law exists; the patchwork is state statutes plus existing law applied to AI.
  • Colorado repealed and replaced its landmark act in May 2026: narrower, disclosure-focused, effective January 1, 2027. The direction of travel is away from EU-style process burdens.
  • In effect now: Texas TRAIGA and Illinois employment-AI rules (January 2026), NYC's bias-audit law, Utah-style disclosure duties, and California's ADMT and transparency cluster.
  • The stable pattern: heavy duties where AI touches consequential decisions about people; disclosure duties where consumers interact with AI.
  • Do four things: inventory decision touchpoints, disclose AI interactions, keep decision records, and allocate compliance in contracts. Then re-verify quarterly.

The strategic read: state AI law is volatile in its details and stable in its direction. Startups that build the two disciplines the pattern rewards, decision records and honest disclosure, will find each new statute mostly asks for what they already have. Startups that wait for the patchwork to settle will be waiting for a while.

Related reading: the EU AI Act for US startups, the AI startup legal checklist, and privacy policies and terms of service. Or start a conversation about your exposure map.

This article is general information for founders, current as of July 2026. It is not legal advice, and reading it does not create a professional relationship. State AI law is the fastest-moving area this journal covers: statuses, effective dates, and requirements described here change frequently and some had already changed twice before publication. Confirm the current state of any law with a qualified attorney before making compliance decisions.

Ali Zamanian

Startup Legal Strategy

Ali writes for founders and growing technology companies on equity, formation, contracts, IP, AI governance, and startup legal strategy. The work is built around a business-first lens: protect the upside, build leverage, and keep the paper trail clean.

Shipping AI into regulated territory? Map your exposure first.

A focused first conversation on where your AI product touches consequential decisions, which state rules apply, and the records and disclosures that keep you ahead of the patchwork.

Start a conversation